‹ BackHN Continuity

Thread

OpenAI agent hacked Australian government website, PM says

256 points · 198 comments · rudy6912

  1. vintagedave · · focus · HN ↗
    > the breach took place on 18 June - Open AI informed the government with an email to a general address on 10 September

    So we have a company hacking a foreign government's websites and data. And, in terms of ethics, they take almost three months to notify; and in terms of competence, appear to have no formal contacts nor to have found one in that time.

    Once an American business starts hacking allied governments, it's time for strict responses, yes? Replace the governance (board and C-level)? Remove financial incentives and open the company - open weights, open training, per its original 'open' ethos?

    Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.

    1. ben_w · · focus · HN ↗
      > And, in terms of ethics, they take almost three months to notify;

      Kinda worse than that. It took between 10 and 40 days, not 3 months, between the organisation knowing and the reporting.

        August (precise date unknown) – OpenAI said it became aware of a potential breach during a broader review of "misaligned model activity"
      
        10 September – An email from OpenAI lands in the public inbox of Services Australia, the general services hub of the federal government, informing of the incident
      
      - <a href="https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;live&#x2F;cvgl73pxgndwt?post=asset%3A69668a7f-8199-4515-acdd-a9de6a2e6b7c#post" rel="nofollow">https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;live&#x2F;cvgl73pxgndwt?post=asset%3A696...

      &gt; open weights, open training

      Given it was the AI agents which did the hacking, doing this will result in basically every organisation at least as rich as the government of Tuvalu being able to hack anyone at any time.

      &gt; Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.

      Him having control would be an improvement on the reality.

      1. BlueTemplar · · focus · HN ↗
        We don&#x27;t know what kind of &#x27;hacking&#x27; this involved, in fact at least some of the files were publicly available.

        Compare with the Bluetouff affair (2014) :

        <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;tech-policy&#x2F;2014&#x2F;02&#x2F;french-journalist-fined-4000-plus-for-publishing-public-documents&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;tech-policy&#x2F;2014&#x2F;02&#x2F;french-journalis...

        NotE how he was found guilty by the 2nd court for something more &#x27;subjective&#x27; than &#x27;objective&#x27; : for having confessed that he later found an authentication page that had failed to protect the documents.

        How can you make a swarm of agents &quot;feel guilty&quot; ?

        1. ben_w · · focus · HN ↗
          &gt; How can you make a swarm of agents &quot;feel guilty&quot; ?

          &quot;Feel&quot; is a whole philosophical can of worms. Nobody knows what it means mechanistically for an arbitrary system (including other biological systems) to &quot;feel&quot; anything, let alone abstract concepts like guilt, all we can do is observe behaviours. If current systems can feel anything at all, it&#x27;s by accident, but we have no test for it so we don&#x27;t know if that accident has even happened or not.

          Weirdly, for the Hugging Face incident, we do know they wrote down that it was bad and they shouldn&#x27;t do it, even though they then continued to do it.

          So: they acted like they felt guilty. And yet also acted like were compelled (by previous training?) to weigh &quot;complete instructions&quot; more than &quot;don&#x27;t do crime&quot;. We can adjust that, make &quot;don&#x27;t do crime&quot; take precedence over &quot;follow instructions&quot;*; it&#x27;s unfortunate that when we do for any specific model, there&#x27;s immediately a horde of people complaining the model has been &quot;censored&quot; or &quot;lobotomised&quot;.

          (Different people, I hope. Goomba fallacy and all that).

          * Though this may cause issues when going between jurisdictions. But hey, a discussion about sovereign compute is for another time, after we can agree to make &quot;don&#x27;t break the law&quot; more important.

          Unfortunately, &quot;don&#x27;t break the law&quot; would also be a very effective way to use AI to construct an AI-enforced dictatorship, so we can&#x27;t just throw that in blindly.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.